The UAE’s new AI and Data Authority
Businesses should prepare for a more coordinated regulatory landscape by strengthening AI governance, privacy compliance, vendor oversight and accountability before detailed rules emerge, writes Ksenia Andreeva and Shamma Biny Sied of Morgan, Lewis & Bockius.
The establishment of the Federal Authority for Artificial Intelligence and Data (the “Authority”) marks an important shift in the United Arab Emirates’ (“UAE”) technology regulatory landscape. By bringing artificial intelligence, data and digital government functions within a single federal body reporting directly to the Cabinet, the UAE has created an institutional platform that could significantly influence how technology regulation develops over the coming years.
For businesses, however, the key question is not simply what the new Authority is, but what its creation means in practice. The immediate effect is unlikely to be a sudden wave of new compliance obligations. Rather, the announcement signals that the UAE is moving towards a more coordinated and potentially more active framework for AI and data governance. For in-house legal teams, that is a strong reason to review existing governance arrangements now, before more detailed rules, guidance and enforcement expectations emerge.
A MORE COHERENT REGULATORY STRUCTURE
Until now, responsibilities relevant to AI, data and digital government have sat across several institutions. The new Authority brings together the UAE Artificial Intelligence Office, the Information and Digital Government Sector of the Telecommunications and Digital Government Regulatory Authority, and the Emirates Data Office.
That consolidation matters because businesses rarely experience AI, privacy and digital regulation as separate issues. A single AI deployment can raise questions about personal data, cybersecurity, intellectual property, and sector-specific obligations. Where multiple regulators or policy bodies are involved, uncertainty over responsibility can make compliance more difficult.
A centralised Authority creates the possibility of a more coherent approach. Its broad mandate includes developing national policy, proposing legislation and strategies, setting standards and guidelines and promoting alignment across federal and local initiatives. In time, this could translate into clearer expectations for businesses deploying AI or processing data in the UAE.
There are, however, important questions still to be answered. The precise boundary between the Authority and existing regulators remains to be seen, particularly in regulated sectors and in areas such as connected devices and the Internet of Things. Businesses operating across the mainland, financial free zones and sector-specific regulatory regimes will therefore need to continue assessing which rules and regulators apply to particular activities.
THE PERSONAL DATA PROTECTION LAW MAY BE THE FIRST MAJOR TEST
For many organisations, the most significant issue is what the new structure could mean for the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, the PDPL).
The PDPL has been in force for several years, but key aspects of its practical application remain dependent on regulations that have not yet been issued. Questions around matters such as lawful processing, data subject rights, international transfers and breach notification continue to require further detail.
The creation of the Authority may provide the institutional basis for that position to change. It is reasonable to expect close market attention on whether the Authority assumes a leading role in progressing the PDPL framework.
For businesses, the prudent approach is not to wait for certainty before acting. The core principles underpinning modern data protection regimes are already familiar: transparency, purpose limitation, data minimisation, security, accountability and appropriate control over transfers and third parties. Organisations that embed those principles into AI governance now will be better placed to respond if the PDPL framework becomes more operational in the near term.
AI GOVERNANCE SHOULD MOVE FROM POLICY TO PROCESS
Many companies have already adopted internal AI policies, particularly in response to the rapid uptake of generative AI. The next stage is to move beyond high-level rules and build a repeatable governance process.
The starting point is visibility. An organisation cannot govern AI effectively if it does not know where AI is being used. In practice, that can be difficult because AI functionality is increasingly built into software that businesses already use, from HR and recruitment tools to cybersecurity products, analytics platforms, customer service systems and productivity software.
Businesses should therefore consider maintaining an inventory of material AI use cases. That inventory should identify the system, its business purpose, the teams using it, the types of data involved, whether a third-party provider is engaged and who is accountable internally for the deployment.
From there, organisations can apply a risk-based review. Not every use of AI requires the same level of scrutiny. A tool used to summarise internal administrative material is different from a system used to assess job applicants, make credit-related recommendations, profile customers or influence decisions with legal or similarly significant consequences.
Higher-risk use cases should trigger enhanced review by legal, privacy, cybersecurity and, where relevant, compliance or ethics functions. Organisations should define those escalation criteria in advance rather than relying on ad hoc judgement each time a new tool is proposed.
DATA GOVERNANCE AND AI GOVERNANCE ARE CONVERGING
One of the most important practical consequences of the UAE’s new institutional structure is the increasingly close relationship between AI governance and data governance.
Legal teams should be asking basic but important questions about every significant AI deployment: what data is being used, where it came from, whether it includes personal or sensitive information, where it is processed, who can access it, how long it is retained and whether the provider can use it for model training or product improvement.
These questions are particularly important for generative AI systems because users may enter confidential, personal or proprietary information into tools without appreciating how that information is handled. Clear internal rules should therefore govern what employees may upload and which systems are approved for particular categories of data.
Existing privacy impact assessment processes can often be adapted to AI rather than creating an entirely separate compliance architecture. The objective should be to connect AI review with established controls around data classification, security, retention, international transfers and third-party management.
VENDOR DILIGENCE WILL BECOME INCREASINGLY IMPORTANT
Most businesses will consume AI through third-party products rather than build models themselves. That makes supplier diligence one of the most important areas for in-house legal teams.
Procurement processes should examine how a provider uses customer data, whether prompts or outputs are retained, whether information is used to train models, where processing occurs, what subcontractors are involved and what security controls apply. The answers should inform both the risk assessment and the contract.
Contractual provisions may need to address permitted data use, confidentiality, cybersecurity, incident notification, intellectual property, regulatory cooperation and responsibility for outputs. Businesses should also consider whether vendors are required to provide sufficient information about material changes to their systems. AI products can evolve rapidly, and a tool assessed at procurement may operate differently several months later.
HUMAN OVERSIGHT AND ACCOUNTABILITY STILL MATTER
Where AI supports consequential decisions, organisations should identify who remains responsible for the final outcome and what meaningful human review looks like. A nominal human approval step is of limited value if the reviewer does not understand the system, lacks relevant information or routinely accepts automated outputs without challenge.
Policies should therefore address both technical and human controls. Employees need training on the limitations of AI, including the possibility of inaccurate or fabricated outputs, bias, confidentiality risks and inappropriate reliance on automated recommendations.
For in-house teams, documenting these arrangements is equally important. Organisations should be able to show how higher-risk systems were assessed, who approved them, what safeguards were adopted and how risks are monitored over time.
PREPARING FOR A FRAMEWORK THAT IS STILL EVOLVING
The establishment of the Authority represents an important step in the continued development of the UAE’s AI and data regulatory framework. By bringing these functions together within a single federal body, the UAE has created a platform for greater coordination and for the development of further guidance, standards and regulatory measures as the framework continues to evolve.
With a broad mandate spanning AI and data policy, standards and regulatory development, the Authority is well positioned to play an important role in shaping the UAE’s approach in these areas. Organisations should therefore anticipate increasingly structured expectations around AI and data governance and consider how their existing compliance frameworks can adapt as further guidance and requirements emerge.
For in-house legal teams, the most effective response is therefore readiness rather than prediction. Businesses do not need to anticipate every rule that may emerge. They do need to understand where AI is being used, establish proportionate governance, connect AI and privacy compliance, strengthen vendor controls, preserve meaningful human oversight and keep adequate records.
Those measures are valuable regardless of the precise form future regulation takes. More importantly, they give organisations the ability to adapt quickly as the Authority begins to define its priorities and the UAE’s regulatory framework continues to mature.
For businesses operating in one of the world’s most ambitious AI markets, that adaptability may prove to be as important as compliance itself.
Text by:

- Ksenia Andreeva, partner, Morgan, Lewis & Bockius LLP
- Shamma Biny Sied, associate, Morgan, Lewis & Bockius LLP







































































































































